How to Calculate the Real Cost of a Third-Party Breach

How to Calculate the Real Cost of a Third-Party Breach

Calculating the real financial impact of a third-party breach is one of the hardest challenges in cybersecurity today. In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik explore how organizations can move beyond vague warnings about risk and start putting real numbers behind the potential cost of a third-party breach. If you want security leaders, executives, and boards to take third-party cyber risk seriously, you need to understand how to quantify its financial impact.

Many security teams still rely on qualitative risk language like “high,” “medium,” or “critical,” but those labels rarely drive action. Jeffrey, Bob, and Ferhat break down why calculating the financial impact of a third-party breach is essential for communicating with executives, prioritizing vendors, and securing the right investments in risk management. From understanding uncertainty to building models that are accurate enough to guide decisions, this conversation offers practical insight into how leading teams estimate breach costs and translate cyber risk into business language.

In this episode, you’ll learn:

  • Why calculating the financial impact of a third-party breach is critical for executive decision making

  • How security leaders translate cyber risk into dollars, euros, or pounds

  • Why “something bad could happen” is not enough to justify cybersecurity investment

  • The difference between precision and usefulness when modeling cyber risk

  • How risk quantification helps prioritize vendors and third-party exposures

  • Why boards and executives respond better to financial risk than technical risk language

Don’t risk letting third-party cyber risk remain invisible to leadership. Learn how to calculate the real financial impact of a third-party breach and turn risk conversations into decisions that protect your organization.


0:00 Introduction & Teaser

0:50 Welcome & Episode Overview

2:01 Guest Introduction: Jack Jones & the Origin of FAIR

7:17 Challenges to Implementing Risk Quantification

10:57 Wrap-Up with Jack Jones

11:23 Calculating Financial Impact of a Third-Party Breach

25:54 Precision vs. Accuracy in Risk Models

30:01 Research Roundup: Cybersecurity Outlook 2026

36:44 Agree or Disagree

39:41 Outro & Next Episode Preview

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(27)

Is AI the End of Humanity or Just Another Y2K?

Is AI the End of Humanity or Just Another Y2K?

Some of the people building AI are warning it could end humanity. Others say it's all hype. Meanwhile, AI agents have already escaped a testing sandbox and attacked another company's infrastructure. S...

23 Sep 37min

Are Your Vendors Lying to You?

Are Your Vendors Lying to You?

Your vendor says they have MFA everywhere. They say their data is encrypted. They say the right things on every questionnaire you send. So why is there almost always a gap between what a vendor tells ...

9 Sep 35min

The AI Scanner Hype Test

The AI Scanner Hype Test

AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent....

26 Aug 37min

Your TPRM Program Isn't Fixable

Your TPRM Program Isn't Fixable

Your third-party risk program is probably built on questionnaires, and you already know they don't really work. So the real question is not how to make them better. It's whether you should tear the wh...

12 Aug 37min

You Can't Say No to Your Vendors

You Can't Say No to Your Vendors

You can't actually say no to a vendor. Ask any room of CISOs how many of them have the power to walk away from a vendor relationship over cyber risk, and the honest answer is almost none. So if levera...

29 Jul 41min

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Why Manufacturing Supply Chains Are Ransomware’s Favorite Target

Manufacturing cybersecurity risk is rising faster than most organizations realize—and many teams are still missing the basics. In this episode, we break down manufacturing cybersecurity risk and why t...

15 Jul 33min

The #1 Mistake Boards Make on Cyber Risk

The #1 Mistake Boards Make on Cyber Risk

Cyber risk communication with boards is broken—and most organizations don’t realize how much it’s costing them. In this episode, we unpack cyber risk communication with boards and reveal why even well...

1 Jul 32min

The Hidden Signals Predicting Vendor Collapse

The Hidden Signals Predicting Vendor Collapse

Third-Party Risk Prediction is the future of cybersecurity, but can you actually predict when a vendor will fail? In this episode of Third Party, we explore third-party risk prediction and whether for...

17 Jun 37min

Populært innen Teknologi

teknisk-sett
lydartikler-fra-aftenposten
energi-og-klima
rss-ki-praten
elektropodden
hans-petter-og-co
smart-forklart
rss-alt-som-gar-pa-strom
rss-snakk-om-sikkerhet
fornybaren
shifter
rss-ai-forklart
tomprat-med-gunnar-tjomlid
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
teknologi-og-mennesker
pedagogisk-intelligens
nasjonal-sikkerhetsmyndighet-nsm
rss-alt-vi-kan
rss-ki-til-kaffen
plattformpodden